← Back
CWE-20

12,724 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,724)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Opera
1Opera Browser
Apr 29, 2026
Oct 21, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Opera before 10.63 allows remote attackers to cause a denial of service (application crash) via a Flash movie with a transparent Window Mode (aka wmode) property, which is not properly handled during navigation away from...Show more
Opera before 10.63 allows remote attackers to cause a denial of service (application crash) via a Flash movie with a transparent Window Mode (aka wmode) property, which is not properly handled during navigation away from the containing HTML document.Show less
1Opera
1Opera Browser
Apr 29, 2026
Oct 21, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Opera before 10.63 allows user-assisted remote web servers to cause a denial of service (application crash) by sending a redirect during the saving of a file.
1Opera
1Opera Browser
Apr 29, 2026
Oct 21, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Opera before 10.63 does not ensure that the portion of a URL shown in the Address Bar contains the beginning of the URL, which allows remote attackers to spoof URLs by changing a window's size.
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Oct 21, 2010
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Google Chrome before 7.0.517.41 does not properly handle element maps, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to "stale elements."
3Debian
GoogleOpensuse
3Chrome
Debian LinuxOpensuse
Apr 29, 2026
Oct 21, 2010
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Google Chrome before 7.0.517.41 does not properly handle animated GIF images, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted image.
1Google
1Chrome
Apr 29, 2026
Oct 21, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Google Chrome before 7.0.517.41 does not properly handle the unloading of a page, which allows remote attackers to spoof URLs via unspecified vectors.
1Google
1Chrome
Apr 29, 2026
Oct 21, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Google Chrome before 7.0.517.41 does not properly perform autofill operations for forms, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a craf...Show more
Google Chrome before 7.0.517.41 does not properly perform autofill operations for forms, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted HTML document.Show less
1Google
1Chrome
Apr 29, 2026
Oct 21, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Google Chrome before 7.0.517.41 does not properly handle forms, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted HTML document.
1Bareftp
1Bareftp
Apr 29, 2026
Oct 20, 2010
N/A· v4
N/A· v3
6.9 MEDIUM· v2
bareFTP 0.3.4 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
1G.rodola
1Pyftpdlib
Apr 29, 2026
Oct 19, 2010
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The ftp_QUIT function in ftpserver.py in pyftpdlib before 0.5.0 allows remote authenticated users to cause a denial of service (file descriptor exhaustion and daemon outage) by sending a QUIT command during a disallowed...Show more
The ftp_QUIT function in ftpserver.py in pyftpdlib before 0.5.0 allows remote authenticated users to cause a denial of service (file descriptor exhaustion and daemon outage) by sending a QUIT command during a disallowed data-transfer attempt.Show less
1G.rodola
1Pyftpdlib
Apr 29, 2026
Oct 19, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
FTPServer.py in pyftpdlib before 0.2.0 allows remote attackers to cause a denial of service via a long command.
1Realnetworks
2Realplayer
Realplayer Sp
Apr 29, 2026
Oct 19, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
rjrmrpln.dll in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, and RealPlayer Enterprise 2.1.2 does not properly validate file contents that are used during interaction with a heap buffer, wh...Show more
rjrmrpln.dll in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, and RealPlayer Enterprise 2.1.2 does not properly validate file contents that are used during interaction with a heap buffer, which allows remote attackers to execute arbitrary code via crafted Name Value Property (NVP) elements in logical streams in a media file.Show less
1Realnetworks
2Realplayer
Realplayer Sp
Apr 29, 2026
Oct 19, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Array index error in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.0.1 allows remote attackers to execute arbitrary code via malformed sample data in a RealMedia .IVR file, related to a "malfo...Show more
Array index error in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.0.1 allows remote attackers to execute arbitrary code via malformed sample data in a RealMedia .IVR file, related to a "malformed IVR pointer index" issue.Show less
1Infradead
1Openconnect
Apr 29, 2026
Oct 14, 2010
N/A· v4
N/A· v3
6.4 MEDIUM· v2
OpenConnect before 2.25 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary AnyConnect SSL VPN servers via a crafted server certificate that (1) does not correspond...Show more
OpenConnect before 2.25 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary AnyConnect SSL VPN servers via a crafted server certificate that (1) does not correspond to the server hostname or (2) is presented in circumstances involving a missing --cafile configuration option.Show less
1Microsoft
3Excel
OfficeOpen Xml File Format Converter
Apr 29, 2026
Oct 13, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel...Show more
Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Ghost Record Type Parsing Vulnerability."Show less
1Microsoft
3Excel
OfficeOpen Xml File Format Converter
Apr 29, 2026
Oct 13, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a cr...Show more
Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Out-of-Bounds Memory Write in Parsing Vulnerability."Show less
1Microsoft
3Excel
Excel ViewerOffice Compatibility Pack
Apr 29, 2026
Oct 13, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Microsoft Excel 2002 SP3 and 2007 SP2; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly validate record information, which allows remote attackers to e...Show more
Microsoft Excel 2002 SP3 and 2007 SP2; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Real Time Data Array Record Vulnerability."Show less
1Microsoft
1Excel
Apr 29, 2026
Oct 13, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Microsoft Excel 2002 SP3 does not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Extra Out of Boundary Record Parsing Vulnerability."
1Microsoft
2Excel
Office
Apr 29, 2026
Oct 13, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Microsoft Excel 2002 SP3 and 2003 SP3, and Office 2004 for Mac, does not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Negati...Show more
Microsoft Excel 2002 SP3 and 2003 SP3, and Office 2004 for Mac, does not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Negative Future Function Vulnerability."Show less
1Microsoft
2Excel
Office
Apr 29, 2026
Oct 13, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Merge Cell Record Pointer Vulnerabi...Show more
Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Merge Cell Record Pointer Vulnerability."Show less